Autodream

Security checks across malware telemetry and agentic risk

Overview

Autodream is a disclosed memory-cleanup skill that can rewrite agent memory, so it should be used deliberately but does not show malicious behavior.

Install only if you want an agent to maintain long-term memory files. Verify the external autodream script or npm package, run with --dry-run first, review the proposed MEMORY.md changes, and keep backups enabled before allowing heartbeat-based automatic runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes very generic phrases such as "dream" and "organize memory," which can be used in ordinary conversation and may cause unintended skill activation. Because this skill performs file analysis and rewrites a shared MEMORY.md, accidental invocation could lead to unwanted modification of persistent agent memory and indirect privacy or integrity issues.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage guidance allows contextual activation based on vague conditions like periodic heartbeat checks and "after major events," which are subjective and can cause the skill to run without clear user intent. In this context, automatic consolidation affects persistent memory files, so ambiguous automation increases the risk of unintended state changes, loss of useful entries through pruning, and surprise background processing.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal